I'd argue if you let even audited firmware generate your seed, you're shifting trust to the audit. Unfortunately, it appears nobody audited.
Would you say hand rolling and hashing requires trust? Genuinely asking, for the sake of exploring my own thoughts on this.
